Privacy Policy

Your business data deserves serious protection

Last updated: June 22, 2026

You Call the Shots

Toggle any data sharing on or off from your dashboard—no hoops to jump through.

Not for Sale. Period.

We make money from subscriptions, not from selling your business intelligence.

Your Data, Protected

AES-256 encryption for sensitive data, secure password hashing, and rate-limited APIs.

1. Information We Collect

We collect information you provide directly, including:

  • Account information (name, email, company, phone number)
  • Uploaded documents and data files for AI analysis
  • Usage data and interaction logs to improve our services
  • Payment information processed securely through Stripe
  • Communications with our support team

When you visit our public website, we also collect limited information automatically — with your consent where required — including device and browser details, pages viewed, and approximate location. If you consent to marketing cookies, our visitor-identification provider may associate your visit with the business you appear to be browsing from (and, for U.S. visitors, a likely individual). See Section 7 for details and controls.

2. How We Use Your Information

  • Powering Your Business: Running your dashboards, generating insights, and delivering the intelligence features you use daily
  • Platform Improvement (opt-in): When you enable this option, anonymized patterns from your usage help us sharpen our algorithms and surface better recommendations across the platform
  • Keeping You Informed: Account updates, billing notices, and occasional product announcements that help you get more value from Xpherium
  • Understanding Usage: Aggregate analytics (no personal identifiers) help us know which features resonate and where we should focus development
  • Protecting the Platform: Monitoring for unusual activity to keep your account and data secure

You're in the Driver's Seat: Every data-sharing option in Xpherium is controlled through clear toggles in your Privacy Settings. Want to contribute to platform improvements? Great. Prefer to keep everything private? That works too. Your business, your rules.

3. Data Security

We implement the following security measures:

  • AES-256 encryption for sensitive data fields
  • HTTPS/TLS encryption for all data in transit
  • Secure password hashing with bcrypt
  • Two-factor authentication (2FA) option
  • Role-based access controls for team management
  • Rate limiting to prevent abuse
  • JWT-based session management

4. Who Sees Your Data

We don't sell your data. Our business model is subscriptions, not advertising.

The only times your data may be shared:

  • Service Providers: Cloud hosting and payment processing partners who help us run the platform
  • Analytics & Marketing Partners: Consent-based website measurement and visitor-identification providers (Google Analytics, LinkedIn, and RB2B) — only active when you accept analytics/marketing cookies
  • Legal Requirements: When required by law or valid legal process
  • Business Transfers: If Xpherium is acquired, your data protection rights remain intact
  • Your Integrations: When you explicitly connect third-party services

5. What You Can Do

No legal degree required—here's what you can do with your data:

  • Download Everything: One click gets you a complete export of your account data
  • Fix Mistakes: Edit your profile info whenever you spot something wrong
  • Delete Your Account: We'll wipe your data within 30 days of your request
  • Turn Off Emails: Unsubscribe from marketing with a single toggle
  • Take Your Data: Export in JSON format to move or analyze elsewhere
  • Limit Usage: Restrict how we process your data beyond essentials

All of this lives in Settings → Security & Privacy. No support tickets needed.

6. Data Retention

We retain your data for as long as your account is active or as needed to provide services. When you delete your account:

  • We delete your personal data and uploaded files
  • Anonymized, aggregated analytics may be retained
  • Billing records may be retained as required by law
  • You can export your data before deletion via Settings

7. Cookies & Tracking Technologies

We use two categories of cookies. You choose what we set on your browser the first time you visit, and you can change your mind at any time using the button below.

Strictly necessary — always on

Required for the site to work. These cannot be disabled.

  • xph_session — HttpOnly, Secure session cookie used to keep you signed in. Expires when you log out or after 7 days, whichever comes first.
  • xph_dashboard_theme — remembers your light/dark preference.

Analytics — opt-in only

Google Analytics 4 helps us understand which pages and features visitors use so we can improve the product. Loaded only after you accept the analytics category.

  • _ga, _ga_<id> — set by Google Analytics 4 to distinguish visitors. We run GA with IP anonymization enabled and advertising / personalization signals disabled.

Marketing & visitor identification — opt-in

These help us measure marketing campaigns and recognize the businesses interested in Xpherium so our team can follow up. They load only after you accept the marketing category (see the regional note below).

  • LinkedIn Insight Tag (li_*, lidc, bcookie, UserMatchHistory) — measures ad conversions and helps us reach relevant audiences on LinkedIn.
  • RB2B website visitor identification — recognizes the company behind a visit, and for visitors in the United States may identify the likely individual (name, professional profile, business email) by matching against a permissioned third-party data network. We use this to understand which businesses are evaluating Xpherium and to enable relevant, business-to-business follow-up. Person-level identification is limited to U.S. traffic.

Where you are matters. In the EU, EEA, and UK, analytics and marketing / visitor-identification technologies load only after you opt in. In the United States and other regions they may load by default, and you can opt out at any time with "Reject all" or the button below.

We do not use session-replay tools, and we do not sell the data these cookies generate. If we add a new tracking technology, we'll update this page and the consent banner before activating it.

8. International Data Transfers

Your data may be processed on servers located in the United States. We take steps to protect your data including:

  • Using reputable cloud providers with their own security certifications
  • Encrypting data in transit and at rest
  • Providing data export and deletion tools to support your privacy rights

Contact Us

For privacy-related questions, data requests, or to exercise your rights:

📧 Email: privacy@xpherium.com

🌐 Privacy Center: xpherium.com/privacy

We aim to respond to all privacy inquiries within 48 hours.